CVE-2026-26034Disclosure(dell / ups_multi-ups_management_console)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute arbitrary code with SYSTEM privileges by causing the application to load a specially crafted DLL.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-276CWE-428

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ups_multi-ups_management_console

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
ups_multi-ups_management_console

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-08: 1Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-08: 103-0503-0603-08
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-051
General1
2026-03-061
Disclosure1
2026-03-081
Disclosure1
Full discourse3 posts
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2026-26034: Dell UPS console—DLL sideloading → SYSTEM. The thing you plug in and forget for 10 years. Default permissions enable hijacking. Datacenters, hospitals, industrial sites. Even your battery management software is an attack vector now. Scope: existential.

    Post summary

    Dell UPS console firmware is vulnerable to DLL sideloading that can grant SYSTEM privileges, exposing datacenters, hospitals, and industrial sites to serious risks.

    0001053
    5 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26034 UPS Multi-UPS Management Console (MUMC) version 01.06.0001 (A03) contains an Incorrect Default Permissions (CWE-276) vulnerability that allows an attacker to execute … https://www.cve.org/CVERecord?id=CVE-2026-26034

    Post summary

    The text announces CVE-2026-26034, noting it as an Incorrect Default Permissions vulnerability in UPS MUMC v01.06.0001 that permits code execution, but offers no information on exploits or patches.

    00000230
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-26034 UPS MUMC 01.06.0001 Incorrect Default Permissions Leads to Arbitrary Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26034

    Post summary

    The post reports CVE-2026-26034 as an arbitrary code execution flaw in UPS MUMC due to incorrect default permissions, without mentioning any PoC, exploit code, patch, or active exploitation evidence.

    0000054
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdellups_multi-ups_management_console01.06.0001_\(a03\)--

Explore more